feat(leases): expose owner-authenticated connection display name - #11910
Merged
diegosouzapw merged 3 commits intoAug 30, 2026
Merged
diegosouzapw merged 3 commits into
diegosouzapw merged 3 commits into
Conversation
KaspaPulse
force-pushed
the
feat/lease-account-visibility-v1-20260828
branch
from
August 28, 2026 15:23
6f92593 to
7f27627
Compare
KaspaPulse
force-pushed
the
feat/lease-account-visibility-v1-20260828
branch
from
August 28, 2026 15:28
7f27627 to
832265e
Compare
KaspaPulse
marked this pull request as ready for review
August 28, 2026 15:58
Bring inherited Fast Quality Gates / ESLint / unit-test / docs-sync fixes from diegosouzapw#11940/diegosouzapw#11955/diegosouzapw#11975. Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
diegosouzapw
merged commit Aug 30, 2026
81bf1ef
into
diegosouzapw:release/v3.8.51
14 of 15 checks passed
5 tasks
5 tasks done
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…gosouzapw#11910) Boarded with 8 other PRs in one combined worktree: typecheck:core, check:file-size, check:changelog-integrity, check:complexity, check:cognitive-complexity, check:cycles, check-native-deps all green; 75/75 focused tests pass. Reviewed the security fencing closely — the status query fences on lease_owner_hash + api_key_id + generation + state=ACTIVE + not-expired, gated behind the existing lease:exclusive scope check. configuredConnectionName() correctly excludes email-derived fallback labels from the response. Test coverage explicitly verifies foreign key / different owner / stale generation all fail closed with 409, and no metadata leaks for released/expired/invalidated/missing leases. Thanks for the careful privacy-safe design.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
{"action":"status","generation":N}action toPOST /api/v1/session-leases.codex-omniclient follow-up.Example status response:
{ "state": "ACTIVE", "generation": 1, "acquiredAt": "2026-08-28T12:00:00.000Z", "renewedAt": "2026-08-28T12:00:30.000Z", "expiresAt": "2026-08-28T12:02:30.000Z", "connection": { "displayName": "Primary Codex", "provider": "codex" } }Related issues
Why this server PR is needed
OmniRoute already knows which connection owns an exclusive lease, but the lease-owning client has no privacy-safe API for reading that configured label.
The authenticated Sessions dashboard added by #11389 helps administrators, but it does not allow
codex-omnito truthfully display the active connection inside the user's terminal.This PR supplies that missing authenticated server contract. It does not modify stock
openai/codexor its built-in/statuscommand.Security and compatibility contract
409 LEASE_FENCE_STALEwithout connection metadata.displayNameuses only the trimmed operator-configured connection name.null.connectionobject is populated only for an explicit successfulstatusaction.Codex-omni follow-up and fastest user-visible path
If this server contract is accepted and merged, I plan to submit a separate follow-up PR for the component that owns
codex-omni.A separate PR is necessary because this contribution defines and secures the authenticated OmniRoute API, while the follow-up consumes that API and changes what the user sees in the terminal.
Fastest implementation path
The first usable integration does not require modifying stock Codex
/status.After
codex-omniacquires or restores an exclusive lease and knows its current generation, it calls:{"action":"status","generation":1}through
POST /api/v1/session-leases, using the same managed credentials and exact owner/session identity.When the session starts,
codex-omniprints the returned privacy-safe label:After a legitimate lease transition or failover, it calls the same status action again and displays the newly bound connection, never the old binding.
When no active binding exists, it displays a neutral state without exposing a connection label:
This is a control-plane lookup only. It sends no model prompt, consumes no model quota, and does not alter routing or exclusivity behavior.
Optional
/omni-statuscommandA later client follow-up may also provide:
This is possible only if
codex-omniowns or can safely intercept the command layer.If command interception is not available, displaying the connection during session startup and after transitions remains the fastest usable solution.
Adding the connection to stock Codex's built-in
/statuswould require a separate contribution toopenai/codex. That work is not required for the initial usablecodex-omniintegration.User-visible benefit of the follow-up
Tests added or updated
tests/unit/session-leases-route.test.tscovers:fetchis intercepted so no real provider or model call can occur.Validation
PR-local validation completed before publication:
git diff --check: passed.Ready-CI remediation
The first Ready-for-review CI run exposed three PR-specific integration issues.
Commit
878a0edcorrected the lifecycle OpenAPI compatibility, capacity-wait wording, and generatedskills/omni-inference/SKILL.mdoutput.Checks directly verified on that remediation head include:
The DAST job on that head did not reach the actual DAST tests. Its runner received a shutdown signal during
Build CLI bundle, and all subsequent DAST steps were skipped. It therefore represents an infrastructure cancellation, not a product-test failure and not a successful DAST result.The branch was subsequently refreshed onto the newer release base. The following section records the authoritative status of the current head.
Current Ready CI status
The branch is currently based on
3b752f9d4cbb79a7db3a444e3d3da75cef9b9bcfwith head8333a0d033e94e5ac22e4260ffe7802568e02504.On this head:
Build (advisory)was cancelled because the hosted runner received a shutdown signal duringnpm run build; no compilation error was reported.The previous inherited-base failure list referred to the superseded base
cab9cdc765e6d8b5a560c606ad134a154a4e3153and no longer describes the current head. Issue #11874 remains historical upstream context.Reviewer notes
codex-omniPR will provide the terminal display described above.